Objectives and stakeholders: Identify primary goals, departments involved, and success criteria.
Current-state assessment: Review existing processes, data structures, reporting needs, and integrations.
Fit-gap analysis: Map your current processes to BST Global capabilities; identify gaps and workarounds.
Define scope: Determine which modules/functions to implement first (phased approach is common).
Solution design and project plan
System architecture: Data model, security roles, access controls, and compliance considerations.
Data migration plan: Source systems, data mapping, data cleansing, and migration timing.
Integration plan: Required interfaces with CRM, payroll, timekeeping, banking, etc.
Phased plan and milestones: Timeline, resource allocation, and go-live dates.
Configuration and development
System configuration: Chart of accounts, project templates, billing rules, workflows, approvals, and reporting dashboards.
Customization (if needed): Custom fields, screens, or logic to support unique business processes.
Integrations: Build and test connectors to ERP add-ons, HR/payroll providers, CRM, time & expense systems, etc.
Security and roles: Define users, roles, permissions, and segregation of duties.
Data preparation and migration
Data cleansing: Normalize and clean data from legacy systems.
Mapping and migration: Migrate financial data, projects, customers, vendors, employees, timesheets, etc.
Validation: Reconcile migrated data and run pilot transactions.
Customisation
Configuration vs. customization
Configuration: Adjusting settings, workflows, templates, dashboards, and security without code changes.
Customization: Add-ons such as new fields, bespoke business rules, or custom integrations that require development.
Customization topics commonly supported
Custom fields and object extensions (e.g., additional project attributes, cost codes, or personnel fields).
Custom workflows and approval processes for timesheets, expense approvals, and project changes.
Custom reporting and analytics (budget vs. actuals, earned value, utilization, profitability by project/client).
Custom integrations with external systems (CRM, payroll, banking, procurement, HRIS, ERP)
Customizations to billing rules, revenue recognition, back-office consolidations, or multi-currency handling.
UI/UX tweaks for specific roles or departments.
Additional Costs
Software licensing / subscription
Per-user or per-seat licensing (often differentiated by role: full ERP user, timesheet/field user, etc.)
Modules included (e.g., Projects, General Ledger, Accounts Payable/Receivable, Payroll, Field Operations, CRM, Analytics)
Implementation services (one-time)
Discovery, design, configuration, data migration, integrations, testing, and training
Typical duration range: a few weeks to several months, depending on scope and whether you’re doing a phased rollout.
Some vendors offer fixed-price or time-and-materials engagements; ensure clear scoping to avoid scope creep.
Setup and configuration fees
Initial environment setup, security role definitions, data mapping templates, and baseline configurations.
Data migration
Data extraction, cleansing, mapping, and validation. Costs depend on data volume and complexity.
Integrations
One-time integration development plus ongoing maintenance fees if there are API-based connectors or middleware.
Ongoing SaaS costs (if hosted)
Monthly/annual subscription fees for access and hosting.
Regular maintenance and minor upgrades typically included in SaaS.
Training
Initial onboarding training
Role-based, hands-on sessions for core roles (project managers, accountants, field supervisors, admins).
Training delivered by a mix of instructor-led sessions (virtual or on-site) and self-paced modules.
Focus areas often include navigation, key workflows (project setup, timesheets, approvals, billing, financials), and basic reporting.
Admin and super-user training
deeper sessions on security model, user provisioning, data governance, dashboards, and advanced configurations.
Administrators learn about integrations, data migration templates, backup/restore basics, and upgrade considerations.
User adoption and change management
Quick-start guides, how-to videos, and issue-resolution playbooks.
Change management support to promote user adoption, sometimes including champions programs or train-the-trainer approaches.
Ongoing training options
Refresher courses for new releases or modules.
On-demand training library and periodic live webinars.
Certification or proficiency tracks for key roles (where offered by the vendor).
Training formats to expect
Virtual classroom or webinar sessions.
On-site workshops (for larger customers or during major implementations).
Documentation: user manuals,_admin guides, and release notes.
Sandboxed environments for practice without risking live data.
Security Measures
Identity and access management
Role-based access control (RBAC) with least-privilege principles.
Strong user provisioning workflows (create, modify, terminate).
Multi-factor authentication (MFA) options in SaaS deployments (when supported).
Data protection
Encryption in transit (TLS) and at rest for cloud deployments.
Data segmentation and tenant isolation (especially in multi-tenant environments).
Data retention controls and export options for compliance needs.
Application and platform security
Regular security patches and vulnerability management integrated into update cycles.
Audit trails and change history for configurations, data changes, and user activity.
Security incident response procedures and defined SLAs for critical issues.
Compliance and governance
Support for industry-specific controls (e.g., SOX-like controls for financial processes, if applicable).
Data localization options by region (for some deployments) and compliance documentation.
Backup and disaster recovery
Regular backups with defined RPO/RTO targets.
Tested recovery procedures and failover options for critical components.
Updates
Update cadence
ERP/PSA vendors typically release major releases annually or semi-annually, with interim patches and hotfixes as needed.
Some SaaS models push automatic minor updates; others schedule maintenance windows with customer notification.
Delivery model
SaaS hosted: Updates are usually deployed by the vendor, with customers receiving release notes and potentially in-product banners describing changes.
On-premises or hosted private cloud: Updates may be scheduled by the customer or the vendor, often requiring testing in a sandbox and a formal upgrade window.
Change management for updates
Release notes detailing new features, deprecations, and configuration impacts.
Compatibility guidance for customizations and integrations.
Upgrade assistance options: migration scripts, data validation templates, and testing guidance.
Testing and validation
Pre-release access or a beta program for customers to validate customizations and integrations.
Customer sign-off required for production go-live after upgrade.
Backward compatibility and deprecations
Vendors typically publish a compatibility matrix and sunset timelines for older modules or APIs.
Change logs indicate any mandatory re-configuration after an update (e.g., new fields, renamed objects).
Data Ownership and Portability
Data ownership
Generally, customers retain ownership of their data stored in the BST Global system.
The vendor typically acts as a data processor/hoster, while the customer is the data controller.
Data access and extraction
Customers should have rights to export their data in a usable format (e.g., CSV, Excel, or structured data extracts) upon request.
Availability of data export tooling or APIs to retrieve project, financial, payroll, and time/expense data.
Data retention and deletion
Policies outlining how long data is retained after contract termination.
Procedures for secure data deletion or anonymization after the wind-down period, in line with regional data protection laws.
Data localization and residency
Regional data centers or data residency options may be available, especially for clients in regulated industries or certain geographies.
Compliance with local data protection regulations (e.g., GDPR in the EU, CCPA in California) often requires clear data handling disclosures.
Data security and access controls
Standard: encryption in transit (TLS) and at rest, role-based access control, and audit trails.
Access to data by BST Global personnel is typically restricted and governed by NDA and access policies.
Data portability commitments
Availability of structured data export formats.
Clear timelines or processes for data migration in case of contract termination or migration to another platform.
Scaling Up / Down
Scaling up (growth)
Additional licenses/users can typically be added, with pricing adjusted for per-user or per-seat licensing.
Module expansions (e.g., add Payroll, Field Operations, Analytics) can be activated in a phased manner.
Implementation and data migration efforts may be required to support expanded scope.
Scaling down (downsizing)
Reducing user counts or modules is usually supported, with adjustments to licensing and subscription fees.
Depending on the contract, there may be minimum commitment periods or notice windows.
Flexibility considerations
Many contracts offer annual or multi-year terms with options to scale at renewal.
Phased deployments can help manage costs during growth or contraction.
Some vendors provide a formal change request process or a documented pricing adjustment at the next renewal.
Cost implications
Upgrades or downgrades typically trigger a revised renewal quote.
Some vendors impose early-termination considerations if you heavily modify scope mid-term; others allow mid-term adjustments with proportional pricing.
The terms & conditions for contract renewal and cancellation
Renewal structure
Typically annual or multi-year renewal options.
Price re-baselining at renewal, potentially with caps or planned increases; renewal terms may include SLA adjustments or feature changes.
Cancellation options
Termination for convenience: might be allowed with notice and possible early-termination fees or refunds depending on unused period.
Termination for cause: breach of contract, non-performance, or failure to meet service levels can trigger termination rights.
Notice and transition
Required advance notice (e.g., 60–90 days) prior to renewal or termination.
Exit planning assistance or transition support to export data and wind down services.
Data handling at end of contract
Deadline for data export, final data delivery windows, and secure data removal from BST Global systems after termination.
Post-termination access to archived data (if any) and format.
Payment terms
Pro-rated charges for partial periods, remaining balances, and any early-termination penalties if applicable.
Settlement of any outstanding professional services or migrations.
Service levels and support post-termination
Availability of transitional support or knowledge transfer during wind-down.
Continuation of critical support options for a defined wind-down period, if offered.
Compliance with governing law and dispute resolution
Renewal may reinforce current SLAs or update them; include uptime, response times, and support coverage in the renewal.
Compliance
SOC 2 (System and Organization Controls) reports and related trust services criteria.
ISO 27001 (information security management) certification or equivalent.
ISO 27017/27018 for cloud security and data privacy in the cloud (where applicable).
GDPR compliance posture for EU data subjects (data processing addendum, data processing agreements, DPA).
Data localization/regulatory compliance as applicable to regions (e.g., HIPAA is not typical for ERP, but relevant to certain industries; verify if healthcare-related data is involved).
PCI-DSS considerations if handling cardholder data (usually not core for ERP, but relevant for integrated payment workflows).